PatchSiren cyber security CVE debrief
CVE-2026-87169 Oracle Corporation CVE debrief
A vulnerability in Oracle Contract Lifecycle Management for Public Sector (component: Wage Determination Online) allows unauthenticated attackers with network access via HTTP to compromise the product. Successful attacks require human interaction and can result in unauthorized update, insert or delete access to some accessible data as well as unauthorized read access to a subset of accessible data.
- Vendor
- Oracle Corporation
- Product
- Oracle Contract Lifecycle Management for Public Sector
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for Oracle Contract Lifecycle Management for Public Sector deployments, especially those with publicly accessible HTTP interfaces, should assess exposure and potential impact. IT teams and security professionals managing these systems need to prioritize verification and remediation efforts.
Why it matters
CVE-2026-87169 is a medium-severity vulnerability in Oracle Contract Lifecycle Management for Public Sector that allows unauthenticated attackers to compromise the product via HTTP, potentially leading to data manipulation and access. Defenders should prioritize verifying exposure, assessing impact, and implementing necessary security measures to prevent unauthorized access and data breaches.
- Potential unauthorized data manipulation and access.
- Scope change impacting additional products.
- Requires verification of exposure and remediation efforts.
- Potential for data breaches and integrity loss.
Technical summary
The vulnerability in Oracle Contract Lifecycle Management for Public Sector (component: Wage Determination Online) is easily exploitable and allows unauthenticated attackers with network access via HTTP to compromise the product. Successful attacks require human interaction from a person other than the attacker and can result in unauthorized update, insert or delete access to some of Oracle Contract Lifecycle Management for Public Sector accessible data as well as unauthorized read access to a subset of Oracle Contract Lifecycle Management for Public Sector accessible data. The CVSS 3.1 Base Score is 6.1 (Confidentiality and Integrity impacts).
Defensive priority
Defenders should prioritize verifying exposure and assessing potential impact on Oracle Contract Lifecycle Management for Public Sector deployments, especially those with publicly accessible HTTP interfaces.
Recommended defensive actions
- Verify Oracle Contract Lifecycle Management for Public Sector deployments for exposure, especially those with publicly accessible HTTP interfaces.
- Assess potential impact on additional products that may be affected by scope change.
- Review and implement necessary security measures to prevent unauthorized access and data manipulation.
- Monitor for any signs of exploitation or anomalous activity.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impacts, and affected versions. However, specific remediation steps or version fixes are not mentioned in the provided sources. Defenders should verify exposure, assess potential impact, and review security measures. The vulnerability affects Oracle Contract Lifecycle Management for Public Sector, specifically component: Wage Determination Online, with versions 12.2.3-12.2.15 being vulnerable. The CVSS 3.1 Base Score is 6.1, indicating medium severity. Successful
Sources and references
Verified primary and authoritative sources
-
CVE-2026-87169 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-87169
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-87169 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87169
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspusep2026.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.